The age commands: pub, priv, encrypt and decrypt (closes #3)
All checks were successful
check / check (push) Successful in 3m57s

The application number is 657169, so the path is
m/83696968'/657169'/<n>'. The 32 derived bytes are clamped the way
X25519 requires and go through bech32 into an age identity, which is
the only route age offers from raw bytes to a key; these are the steps
sneak/secret takes in its agehd package.

The derived recipient is always first in the recipient list, so the
mnemonic that encrypted a file can always read it back. Decrypting
recognises the text form by the line it starts with, so it needs no
flag. A file named with -o is created readable only by its owner,
since a decrypted one is as secret as what went into it.

Model: opus-5
This commit is contained in:
2026-09-07 15:44:08 +00:00
parent 279cba6bcf
commit 73c80ab173
7 changed files with 698 additions and 1 deletions

View File

@@ -5,6 +5,7 @@ import (
"fmt"
"os"
"git.eeqj.de/sneak/keyfunc/internal/cli/age"
"git.eeqj.de/sneak/keyfunc/internal/cli/options"
"git.eeqj.de/sneak/keyfunc/internal/cli/ssh"
"github.com/spf13/cobra"
@@ -29,7 +30,7 @@ func Root() *cobra.Command {
}
options.Add(root)
root.AddCommand(ssh.Command())
root.AddCommand(ssh.Command(), age.Command())
return root
}